Skip to main content
Guidance

Technology assurance

The NCSC’s Technology Assurance activities provide a means to gain confidence in the cyber security of the services and technologies on which the UK relies.

Page 7 of 35

Why technology assurance in the UK needs to change

The Integrated Review of Security, Defence, Development and Foreign Policy 2021, highlights the importance of innovation. It discusses the ambition of equipping our armed forces with cutting-edge cyber capability, and more widely, for the UK to become a “science and technology superpower”, by 2030.

An approach to Technology Assurance that enables these ambitions, whilst keeping the UK and its people secure, is crucial. The current system, as outlined above, does not do this.

The NCSC Assurance strategy maps the way to an approach which not only caters to our current needs but will evolve with us, as the technology we use, and the way we use it, changes.

From critical national infrastructure and the growing online workforce, through to consumer IoT devices, the scale of opportunity and need to assure connected technologies will increase. To capitalise on these opportunities, we must grow an ecosystem of test facilities and expertise that can give us confidence in the cyber security of the technologies we employ.

Paradigm shift

The ways people and groups behave, and how they interact with technology are constantly changing. This makes evolution an inevitable part of cyber security. A static approach to assurance cannot respond to the continued pace of innovation and proliferation of technology. A paradigm shift is called for.

To keep the UK safe, we can no longer solely focus on gaining confidence in cyber security technologies (such as VPNs, firewalls etc). The NCSC must also help people to be able to gain confidence in any technology that needs to be cyber secure.

We also need an assurance approach that facilitates diversity in technology. Technological diversity is important because it requires any attacker to overcome a broader range of defences and thus, makes it harder to harm the UK’s most critical systems.

Published

Reviewed

Version

1.0